Professional Cloud ArchitectDesign and plan a cloud solution architectureHard

A large enterprise needs to ensure that all network traffic between their Google Cloud VPC networks and their on-premises data centers is inspected by a centralized set of firewalls for security and compliance. They want to avoid routing all traffic through a single, potentially bottlenecked location and instead distribute the inspection load across multiple firewall instances. Which Google Cloud networking pattern should they implement?

  1. ADirect Interconnect with route-based VPN
  2. BHybrid Network Firewall Inspection with Gateway Load Balancer and third-party firewalls
  3. CVPC Network Peering with custom route advertisements
  4. DShared VPC with centralized firewall VMs and Cloud VPN
Show answer & explanation

Correct answer: B. Hybrid Network Firewall Inspection with Gateway Load Balancer and third-party firewalls

Hybrid Network Firewall Inspection, leveraging Gateway Load Balancer with third-party virtual firewalls, is designed for this exact scenario. It allows traffic to be transparently redirected to a pool of firewall VMs for inspection, distributing the load and preventing bottlenecks, while maintaining a centralized inspection point for hybrid connectivity.

Why the other options are wrong

  • A. Direct Interconnect provides high-bandwidth, low-latency connectivity, but 'route-based VPN' doesn't inherently solve the problem of transparently distributing inspection load across multiple firewalls for centralized compliance.
  • C. VPC Network Peering is for connecting VPCs within Google Cloud, not for hybrid connectivity to on-premises, and doesn't inherently provide centralized firewall inspection.
  • D. Shared VPC and Cloud VPN establish connectivity, but centralizing inspection with just VMs would likely lead to bottlenecks and lack the transparent, distributed inspection capabilities of Gateway Load Balancer.

Hybrid Network Firewall Inspection

An architectural pattern on Google Cloud that uses Gateway Load Balancer to transparently redirect and distribute hybrid network traffic (on-prem to cloud) to a pool of virtual firewall appliances for centralized security inspection.

  • Uses Gateway Load Balancer for transparent redirection
  • Distributes inspection load across multiple firewall VMs
  • Centralized inspection for hybrid connectivity
  • Prevents bottlenecks, ensures scalability and high availability

Memory trick: Gateway LB + Firewalls: Bridge to Cloud, Scan Everything, No Bottlenecks.

More Design and plan a cloud solution architecture questions